CVE-2006-4565Improper Restriction of Operations within the Bounds of a Memory Buffer in Firefox

Severity
9.3CRITICALNVD
EPSS
10.4%
top 6.77%
CISA KEV
Not in KEV
Exploit
No known exploits
Timeline
PublishedSep 15
Latest updateMay 3

Description

Heap-based buffer overflow in Mozilla Firefox before 1.5.0.7, Thunderbird before 1.5.0.7, and SeaMonkey before 1.0.5 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a JavaScript regular expression with a "minimal quantifier."

CVSS vector

AV:N/AC:M/C:C/I:C/A:CExploitability: 8.6 | Impact: 10.0

Affected Packages6 packages

Debianmozilla/thunderbird< 1.5.0.7-1+3
NVDmozilla/firefox1.5.0.6
NVDmozilla/thunderbird1.5.0.6
debiandebian/firefox< firefox 1.5.dfsg+1.5.0.7-1 (sid)

Patches

🔴Vulnerability Details

2
GHSA
GHSA-xr4c-88wp-frr7: Heap-based buffer overflow in Mozilla Firefox before 12022-05-03
OSV
CVE-2006-4565: Heap-based buffer overflow in Mozilla Firefox before 12006-09-15

💥Exploits & PoCs

1
Exploit-DB
Faq-O-Matic 2.711 - Multiple Cross-Site Scripting Vulnerabilities2006-01-16

📋Vendor Advisories

6
Ubuntu
Mozilla vulnerabilities2006-10-10
Ubuntu
Thunderbird vulnerabilities2006-09-25
Ubuntu
firefox vulnerabilities2006-09-23
Ubuntu
Thunderbird vulnerabilities2006-09-22
Red Hat
security flaw2006-09-15

💬Community

4
Bugzilla
CVE-2006-4565 security flaw2018-08-16
Bugzilla
CVE-2006-4340 Various SeaMonkey security issues (CVE-2006-4253 CVE-2006-4565 CVE-2006-4566 CVE-2006-4568 CVE-2006-4570 CVE-2006-4571)2006-09-14
Bugzilla
CVE-2006-4340 Various Firefox security issues (CVE-2006-4253 CVE-2006-4565 CVE-2006-4566 CVE-2006-4567 CVE-2006-4568 CVE-2006-4569 CVE-2006-4571)2006-09-14
Bugzilla
CVE-2006-4340 Various Thunderbird security issues (CVE-2006-4253 CVE-2006-4565 CVE-2006-4566 CVE-2006-4567 CVE-2006-4570 CVE-2006-4571)2006-09-14